Falhas do tipo CWE-78

4.645 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-4620HIGHOS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.EPSS 1.2%CVE-2024-8684HIGHOS Command Injection vulnerability in Revolution PiEPSS 1.2%CVE-2026-4622HIGHOS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.EPSS 1.2%CVE-2025-53100HIGHRestDB's Codehooks.io MCP Server Vulnerable to Command InjectionEPSS 1.2%CVE-2020-10603—WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.EPSS 1.2%CVE-2025-8613HIGHVacron Camera ping Command Injection Remote Code Execution VulnerabilityEPSS 1.2%CVE-2024-5672HIGHRed Lion Europe: mbNET.mini vulnerable to OS command injectionEPSS 1.2%CVE-2025-5277CRITICALaws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run aEPSS 1.2%CVE-2022-25350HIGHAll versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization. EPSS 1.2%CVE-2022-21810HIGHAll versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization. EPSS 1.2%CVE-2021-43984CRITICALmySCADA myPROEPSS 1.2%CVE-2021-43981CRITICALmySCADA myPROEPSS 1.2%CVE-2021-23198CRITICALmySCADA myPROEPSS 1.2%CVE-2024-37140HIGHDell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an aEPSS 1.2%CVE-2021-22657CRITICALmySCADA myPROEPSS 1.2%CVE-2026-54501CRITICALBrowsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom BehaviorsEPSS 1.2%CVE-2024-57014HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScEPSS 1.2%CVE-2024-43655CRITICALAny authenticated users can execute OS commands as root using the <redacted>.sh CGI script.EPSS 1.2%CVE-2024-25002HIGHCommand Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.EPSS 1.2%CVE-2024-21898HIGHQTS, QuTS heroEPSS 1.2%